CVE-2020-9112
published 2020-10-19CVE-2020-9112: Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.6th percentile
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information, resulting in the elevation of the privilege.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | taurus-an00b_firmware | < 10.1.0.156\(c00e155r7p2\) | 10.1.0.156\(c00e155r7p2\) |
| huawei | taurus-an00b_firmware | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1+deb9u5build0.16.04.1 | 2.1.2-1.1+deb9u5build0.16.04.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xgmm-v76r-g7gj: Taurus-AN00B versions earlier than 10
ghsa_unreviewed·2022-05-24
CVE-2020-9112 [HIGH] CWE-269 GHSA-xgmm-v76r-g7gj: Taurus-AN00B versions earlier than 10
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information, resulting in the elevation of the privilege.
OSV
OpenJPEG vulnerabilities
osv·2020-09-15·CVSS 7.5
CVE-2016-9112 OpenJPEG vulnerabilities
OpenJPEG vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain image files. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2016-9112)
It was discovered that OpenJPEG did not properly handle certain input. If
OpenJPEG were supplied with specially crafted input, it could be made to crash
or potentially execute arbitrary code.
(CVE-2018-20847, CVE-2018-21010, CVE-2020-6851, CVE-2020-8112, CVE-2020-15389)
It was discovered that OpenJPEG incorrectly handled certain BMP files. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2019-12973)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-19
Published